ÅäÖÃFCKÉÏ´«£¨PHP£©
ҪʹÄúµÄFCKeditorÄܹ»Ê¹ÓÃÉÏ´«¹¦ÄÜ£¬Äú±ØÐë½øÐÐÒÔÏÂÅäÖÆ¡£
×¢Ò⣺FCKeditor²»Ö§³ÖÐéÄâĿ¼£¬ÄúµÄ·¾¶ÉèÖö¼ÊÇÕë¶ÔÍøÕ¾¸ùĿ¼µÄ¾ø¶Ô·¾¶¶øÑԵġ£Õâµã¶ÔÓÚ·¢²¼µ½Ô¶³ÌÍøÕ¾Ä¿Â¼µÄ¿ª·¢Õß¼«Îª²»±ã£¬ºóÃæÎÒÃÇ»á¶Ô´Ë½øÐÐÌÖÂÛ¡£
Ò»¡¢´ò¿ªfckeditor\editor\filemanager\upload\php\config.php£¬ÕÒµ½´úÂë$Config['Enabled']£¬½«ÖµÉèÖÃΪtrue¡£
¶þ¡¢½ÓÏÂÀ´¼¸ÐУ¬ÉèÖÃ$Config['UserFilesPath']£¬ÉèÖÃÉÏ´«Â·¾¶¡£
Èý¡¢´ò¿ªfckeditor\fckconfig.jsÎļþ£¬ÕÒµ½´úÂë_FileBrowserLanguage£¬½«ÖµÉèÖÃΪphp¡£½ÓÏÂÀ´Ò»ÐУ¬°Ñ_QuickUploadLanguageÖµÒ²ÉèÖÃΪphp¡£
ÅäÖÃÎļþä¯ÀÀ
Ò»¡¢´ò¿ªfckeditor\editor\filemanager\browser\default\connectors\php\config.php
ÕÒµ½´úÂë$Config['Enabled']£¬½«ÖµÉèÖÃΪtrue;
¶þ¡¢½ÓÏÂÀ´¼¸ÐУ¬ÉèÖÃ$Config['UserFilesPath']£¬ÉèÖÃä¯ÀÀ·¾¶¡£
¹ØÓÚÉÏ´«\Îļþä¯ÀÀ°²È«ÐÔÎÊÌâ
ΪÁ˽â¾öFCKeditor²»Ö§³ÖÐéÄâĿ¼ÎÊÌ⣬ºÍFCKeditorÎļþÉÏ´«µÄ°²È«ÐÔ¿¼Á¼¡£ÎÒÃÇÓбØÒªÔÚÕâÀïµ¥Â۶Դ˽øÐÐÌÖÂÛ¡£
´ò¿ªfckeditor\editor\filemanager\upload\php\config.php£¬ÕÒµ½$Config['UserFilesPath']´úÂ룬ÔÚ´ËÐдúÂë֮ǰ¶¨Òå±äÁ¿$root_path = $_SERVER['PHP_SELF'];
ÖØÐÂÉèÖÃ$Config['UserFilesPath']±äÁ¿µÄÖµ£¬Ê¾ÀýÈçÏ¡£
$Config['UserFilesPath'] = $root_path . ‘ÄúÏëÉÏ´«µÄĿ¼Ãû/’ ;
´ò¿ªfckeditor\editor\filemanager\browser\default\connectors\php\config.php£¬ÕÒµ½´úÂë$Config['UserFilesPath'],ÔÚ´ËÐдúÂë֮ǰ¶¨Òå±äÁ¿$root_path = $_SERVER['PHP_SELF'];
ÖØÐÂÉèÖÃ$Config['UserFilesPath']±äÁ¿µÄÖµ£¬Ê¾ÀýÈçÏ¡£
$Config['UserFilesPath'] = $root_path . ‘ÄúÏëä¯ÀÀµÄĿ¼Ãû/’
ÖÁ´Ë£¬ÄúµÄFCKeditorÒѽâ¾ö²»Ö§³ÖÐéÄâĿ¼ÎÊÌâ¡£½ÓÏÂÀ´£¬ÎÒÃǽéÉÜÒ»ÖÖ¼¼ÇÉÅäÖÃÖ»ÔÊÐí¹ÜÀíÔ±²Å¿ÉÒÔʹÓÃFCKeditorÉÏ´«ÎÊÌâ¡£
½â¾ö·½·¨ÆäʵºÜ¼òµ¥£¬¼ÙÈçÍøÕ¾²ÉÓÃ$_SESSION['admin_id']ÑéÖ¤¹ÜÀíÔ±µÄµÇ¼id£¬ÄúÖ»Ð轫Ïà¹ØµÄ½Å±¾ÎļþÒýÈë¼´¿É¡£È»ºóʹÓÃÏÂÃæµÄ´úÂëÅäÖÃÎļþÉÏ´«\ä¯ÀÀ¿ª¹Ø¡£
¾«¼òFCKeditorÎļþ¿Õ¼ä´óС
FCKeditorĿ¼ÏÂÃæ°üº¬ÓÐÐí¶àʾÀý´úÂ룬ÎĵµµÈ×ÊÔ´£¬ÔÚÎÒÃǵÄW
Ïà¹ØÎĵµ£º
<?
//http://www.jb51.net
class upLoad{
public $length; //ÏÞ¶¨Îļþ´óС
public $file; //ÅжϴËÀàÊÇÓÃÓÚͼƬÉÏ´«»¹ÊÇÎļþÉÏ´«
public $fileName; //ÎļþÃû
public $fileTemp; //ÉÏ´«ÁÙʱÎļþ
public $fileSize; //ÉÏ´«Îļþ´óС
public $error; //ÉÏ´«ÎļþÊÇ·ñÓдí,php4ûÓÐ
public $fileType; //ÉÏ ......
·ÂGOOGLEºÍDiscuz·ÖÒ³º¯Êý(php)
Õâ¸öº¯ÊýÖ»ÐèÒª2¸ö²ÎÊý µ±Ç°Ò³ÂëºÍ×ÜÒ³Êý,$siteÊÇ·¾¶,ÎļþÃû¿ÉÒÔ°´×Ô¼ºµÄÐèÒªÐÞ¸Ä
Õâ¸öº¯Êý²»ÄÜ´«µÝÆäËû²ÎÊý,Èç¹ûÒª´«µÝÆäËû²ÎÊý,ÔÚº¯ÊýÀï×Ô¼º¼ÓÒ»¸ö²ÎÊý¾ÍÐÐÁË
<?php
//¼ÆÊý
$sql = “SELECT count(*) from `andycms_title`;”;
$numrs = mysql_query($sql) or ......
PHPÕýÔò±í´ïʽÖ÷ÒªÓÃÓÚ×Ö·û´®µÄģʽ·Ö¸î¡¢Æ¥Åä¡¢²éÕÒ¼°Ìæ»»²Ù×÷¡£Ê¹ÓÃÕýÔò±í´ïʽÔÚijЩ¼òµ¥µÄ»·¾³Ï¿ÉÄÜЧÂʲ»¸ß£¬Òò´ËÈçºÎ¸üºÃµÄʹÓÃPHPÕýÔò±í´ïʽÐèÒª×ۺϿ¼ÂÇ¡£
ÎÒµÄPHPÕýÔòÈëÃÅ£¬ÊÇÆðÔ´ÓÚÍøÉϵÄһƪÎÄÕ£¬ÕâÆªÎÄÕÂÓÉdzÈëÉîµÄ²ûÊöÁËPHPÕýÔò±í´ïʽʹÓõķ½·¨£¬ÎÒ¾õµÃÊÇÒ»¸öºÜºÃµÄÈëÃŲÄÁÏ£¬²»¹ýѧ³É»¹ÊÇÒª¿¿¸öÈË£¬ÔÚʹÓà ......
¶ÔÓڽű¾°²È«Õâ¸ö»°ÌâºÃÏñÓÀԶûÍêûÁË£¬Èç¹ûÄã¾³£µ½¹úÍâµÄ¸÷ÖÖ¸÷ÑùµÄbugtraqÉÏ£¬Äã»á·¢ÏÖÓÐÒ»°ëÒÔÉ϶¼ºÍ½Å±¾Ïà¹Ø£¬ÖîÈçSQL
injection£¬XSS£¬Path Disclosure£¬Remote commands executionÕâÑùµÄ×ÖÑ۱ȱȽÔÊÇ£¬ÎÒÃÇ¿´ÁËÖ®ºóµÄÓÃ;ÄѵÀ½ö½öÊÇ×¥È⼦?¶ÔÓÚÎÒÃÇÏë×öweb°²È«µÄÈËÀ´Ëµ£¬×îºÃ¾ÍÊÇÄÃÀ´Ñ§Ï°
£¬¿ÉÊÇÍòÎï×¥¸ùÔ´£¬ÎÒà ......